A5_-_Attachment_WRBR_PCI_Data_Protection_Addendum.pdf
PDF 455 KB Posted
- Attached to
- WRBR AUTOMATED FEE MACHINES Federal contract opportunity
- Solicitation number
- 140P5325Q0046
About this file
This is a PCI Data Protection Addendum required for contractors working with Wright Brothers National Memorial on automated fee machines that will handle credit card transactions. The contractor must sign this addendum acknowledging their responsibility to protect cardholder data in accordance with Payment Card Industry Data Security Standard (PCI DSS) requirements.
The contractor must maintain an annual information security program and provide Wright Brothers National Memorial with their annual Report on Compliance (ROC) with PCI DSS and their PA-DSS Implementation Guide upon award and any updates. In case of data breach or suspected compromise, the contractor must provide notice within 48 hours and grant access for investigations by the Memorial's staff, contractors, and law enforcement within 48 hours of written request. The contractor must also provide access for auditing cardholder data protection controls upon written request and return or confirm destruction of cardholder data upon contract termination while continuing to protect any remaining data as required by law and PCI DSS standards.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sol_140P5325Q0046.pdf | ||
| A3_-_Attachment_WRBR_AFM_Section_508_GPAT_Accessibility.pdf | ||
| A4_-_Attachment_IT_and_Security_Requirements.pdf | ||
| A2_-_Price_Schedule.xlsx | XLSX spreadsheet | |
| A1_-_WRBR_AFM_Scope_of_Work_-_Final_-_Revised_7-16-205.pdf | ||
| A6_-_DOL_Wage_Determination.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PCI Data Protection Addendum Requirement
The contractor must sign the following PCI Data Protection Addendum:
Whereas, National Park Service, Wright Brothers National Memorial, is a merchant that conducts transactions that include credit card payments and <contractor> is a service provider that is provided cardholder data or access to cardholder data, both parties must protect cardholder data in accordance to the Payment Card Industry Data Security Standard (PCI DSS).
<Contractor> acknowledges that when it is provided cardholder data or access to cardholder data, it shall protect that data in accordance with requirements specified in the PCI DSS.
<contractor> is responsible to provide protection for all cardholder data that it collects, processes, stored or transmits.
<contractor> shall comply with the following requirements:
• Maintain an information security program to protect cardholder data and validate compliance to the PCI DSS on an annual basis.
• Provide a copy of <contractor> Report on Compliance (ROC) with PCI DSS to Wright Brothers National Memorial on an annual basis.
• Provide a copy of the <contractor> PA-DSS Implementation Guide to Wright Brothers National Memorial upon award and upon any updates to the guide.
• If Wright Brothers National Memorial cardholder data is compromised or suspected to have been compromised while in the possession of <contractor>, provide notice to the client of actual or potential data breach within forty-eight (48) hours.
• Wright Brothers National Memorial is entitled to conduct its own investigation of any data breaches upon written request to <contractor>. Within forty-eight (48) hours of receiving Wright Brothers National Memorial’s written request for investigation, <contractor> shall provide access to its systems and staff and will support both Wright Brothers National Memorial client staff and contractors as well as law enforcement to conduct the investigation.
• Upon written request of Wright Brothers National Memorial, <contractor> shall provide access to the Wright Brothers National Memorial audit cardholder data protection controls.
• In the event that the contract expiration or termination, <contractor> shall return the cardholder data or provide confirmation of cardholder data destruction to Wright Brothers National Memorial. <contractor> shall continue protecting cardholder data to the extent required by law and by the PCI DSS after contract termination.
WRBR AUTOMATED FEE MACHINES
Appendix: PCI Data Protection Addendum
Wright Brothers National Memorial
Contractor Name: ______________________________________
Contract Number: ______________________________________
Name, Title of Contractor PCI DSS Compliance representative:
Signature and Date: ________________________________
PCI Data Protection Addendum Requirement
File details come from the government source that posted it. Updated .